Hacker News new | ask | show | jobs
by setgree 42 days ago
The part about this that's amazing to me is that they still are doing nothing after he noted another GDPR violation [0]. He's obviously both competent and litigious. What does the company expect to happen next??

[0] "Under Article 77(2) of the GDPR a supervisory authority is under a binding legal obligation to keep a complainant informed of the progress and the outcome of their complaint. It is not a courtesy and it is not discretionary - it is written into the law. I filed my complaint with IMY, IMY passed it on, the case ended in a multi-million euro enforcement action, and not one of the authorities involved thought to tell the person who started it."

1 comments

As I understand it, this second complaint is not against the original company, but against the government authority that handled his case.
There's two government authorities here, the one he reported it to (Swedish), and the one that the first one forwarded it to (Norwegian).

The former is the one he seems to be currently taking to task for failing to follow the law, the latter is the one that meaningfully handled the case.

It's also worth noting that it's not the first time Swedish DPA has been criticized regarding GDPR complaint handling:

https://noyb.eu/en/gdpr-rights-sweden "GDPR Rights in Sweden: Court confirms that authority must investigate complaints. So far, the Swedish IMY has taken the view that users don’t have party rights in GDPR procedures."

https://noyb.eu/en/noyb-takes-swedish-dpa-court-refusing-pro... "IMY frequently just forwards a complaint to the company that illegally processes personal data - and then immediately closes the case without investigating." (no decision on this as far as I know. A bit surprising since it has been almost 2 years)

Ah, I got confused by the name and acronyms.